Rob Winch
945e2e2ad4
Fix NPE requestMatchers().mvcMatchers
...
Fixes gh-3969
10 years ago
Marten Deinum
80ff267749
Check RememberMe in ExceptionTranslationFilter
...
This commit adds a check for rememberme to the ExceptionTranslationFilter.
Using this when someone isn't fully authenticated he will be prompted with a
login screen and after that will be redirected to the original requested URI.
Fixes gh-2427
10 years ago
Johnny Lim
69306a8b46
Fix typo ( #3968 )
...
Fixes typo `advantadge`
10 years ago
Rob Winch
8a17c23277
Bump PermGen
10 years ago
Rob Winch
0f608d59b6
Default to Spring IO Athens-SNAPSHOT
10 years ago
Rob Winch
70787fc548
Polish CompositeLogoutHandler
...
Issue gh-3895
10 years ago
Eddú Meléndez
1effc1882a
Add CompositeLogoutHandler
...
Fixes gh-3895
10 years ago
Michael Simons
e5b1cb842e
Document schema changes in CONTRIBUTING.md ( #3965 )
...
Direct changes to XSD schemas will be overwritten by the build, it is necessary that the developer updates the RELAX NG schema instead.
See discussion on commit e297706e8b .
10 years ago
Rob Winch
885f074ddf
Fix XsdDocumentedTests
10 years ago
Rob Winch
e297706e8b
Polish allow unlimitted sessions
...
Update the rnc file
Issue gh-3900
10 years ago
Michael J. Simons
e3ff4130a5
Allow negative values to configure unlimited sessions
10 years ago
Rob Winch
50d7d3287f
Add spring-security-4.2.xsd
10 years ago
Eddú Meléndez
26fa4a4bf0
Prevent HTTP response splitting
...
Evaluate if http header value contains CR/LF.
Reference: https://www.owasp.org/index.php/HTTP_Response_Splitting
Fixes gh-3910
10 years ago
Eddú Meléndez
13b0ddb7e6
Fix test assertions
10 years ago
Rob Winch
b4ab0483b1
Update version to 4.2.0.BUILD-SNAPSHOT
10 years ago
Spring Buildmaster
cc04392d9a
Next development version
10 years ago
Spring Buildmaster
919f000c80
Release version 4.1.1.RELEASE
10 years ago
Johnny Lim
310bb39a0d
Fix typo
10 years ago
Rob Winch
764a4d8414
Fix Error Message typo
...
Fixes gh-3953
10 years ago
Jakob Englisch
b17870ee07
LogoutConfigurer: only allow suitable http methods
10 years ago
Rob Winch
8ad91ef6a5
WithSecurityContextTestExecutionListener > SqlScriptsTestExecutionListener
...
WithSecurityContextTestExecutionListener should order after
SqlScriptsTestExecutionListener so sql can setup the current user's info
in the database.
Fixes gh-3962
10 years ago
Rob Winch
5f6312c5be
Update to Spring 4.3.1
...
Fixes gh-3963
10 years ago
Rob Winch
9d50944cb2
AntPathRequestMatcher implements RequestVariableExtractor
...
Issue gh-3964
10 years ago
Rob Winch
e4c13e3c0e
Add MvcRequestMatcher
...
Fixes gh-3964
10 years ago
Rob Winch
13bc70f693
Add CorsFilter support
10 years ago
Rob Winch
c935d857eb
Add mvc namespace to XmlApplicationContext
10 years ago
Rob Winch
843ed3e437
Update to Spring 4.3.1.BUILD-SNAPSHOT
10 years ago
Rob Winch
7f3b3a8b59
Polish
...
Issue gh-180
10 years ago
Jakob Englisch
261c932b8e
Upgrade Gradle to 2.14
...
Issue gh-3946
10 years ago
Rob Winch
1b4e20e97f
Fix InsecureApplicationTests package
...
Fixes gh-3951
10 years ago
Rob Winch
bd5f71bb0d
Polish
...
Fix checkstyle for LDAP JavaConfig Authority mapping
Issue gh-2768
10 years ago
Tony Dalbrekt
b76e3be822
LDAP Java Config supports GrantedAuthoritiesMapper
...
Fixes gh-2768
10 years ago
Rob Winch
26ad1cb4a5
Polish RememberMe Validation
...
Issue gh-3909
10 years ago
Eddú Meléndez
87224f62e4
RememberMe JavaConfig Validation
...
Add validation when rememberMeServices and rememberMeCookieName are
provided
Fixes gh-3909
10 years ago
Rob Winch
8f880aea0e
Polish Pbkdf2PasswordEncoder
...
Issue gh-3930
10 years ago
vitaliy_kuzmich
5f658b3ffc
Remove double salt in Pbkdf2PasswordEncoder
...
Issue gh-3930
10 years ago
Rob Winch
77a478ba0d
Fix ApacheDSEmbeddedLdifTests checkstyle
...
Issue gh-54
10 years ago
Marcin Zajączkowski
a3c4a5fde7
SEC-2387 - add ignored failing test case
10 years ago
Rob Winch
bbeb7f94d7
Fix checkstyle
...
Issue gh-3920
10 years ago
Rob Winch
a2a06d19c1
Add formLogin() Accept Test
...
Issue gh-3920
10 years ago
Micah Silverman
314828859e
Added accept method call to buildRequest in SecurityMockMvcRequestBuilders with default of MediaType.APPLICATION_FORM_URLENCODED
10 years ago
Rob Winch
66858e22ad
Disable XMLHttpRequest for formLogin entry point
...
Previously the following:
http http://localhost:8080/user \
"X-Requested-With:XMLHttpRequest" "Accept:text/plain"
Produced a 302 instead of a 401
Fixes gh-3887
10 years ago
Rob Winch
2a73f3cdf7
Remove abigious import
10 years ago
Rob Winch
dd9b59ba31
Document Digest is insecure
...
Fixes gh-3894
10 years ago
Eddú Meléndez
39ed7d0eca
Propagate rolePrefix to LdapAuthoritiesPopulator
...
Previous to this commit, custom rolePrefix was not propagated to
LdapAuthoritiesPopulator populating a wrong authority. Now, rolePrefix
is propagated and the authority is as expected.
Fixes gh-3921
10 years ago
Eddú Meléndez
a2ead4cf7a
Polish
...
Fixes gh-3892
10 years ago
Ruben Dijkstra
364db6762e
Add failing test for #3905 Fix Assert usage
10 years ago
Ruben Dijkstra
e8f4ee8a39
Fix Assert usage
10 years ago
Rob Winch
d2b909e7c5
Doc InteractiveAuthenticationEvent doesn't extend AuthentcationEvent
...
Document why InteractiveAuthenticationEvent doesn't extend
AuthentcationEvent. This is to avoid multiple AuthenticationSuccessEvent
from being sent to any listeners.
Fixes gh-3857
10 years ago
Shannon Carey
9fa2c64737
Documentation SecurityConfig->WebSecurityConfig
...
Rename SecurityConfig to WebSecurityConfig in the documentation.
Fixes gh-153
10 years ago